25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

How the HIPAA Omnibus Final Rule Applies to E-mail Communication with Patients

The Omnibus Final Rule was introduced at the start of the year and covered organizations – which now include business associates and their subcontractors – now need to update procedures and policies to comply with the new regulations if they have not already done so. The deadline for compliance with the new rule is September 23, 2013 and any covered entity found not to have implemented the required changes after this date could incur a financial penalty up to $1.5 million. The new changes have been criticized by some members of the healthcare community; however the changes are necessary in order to improve the rights of patients to access their medical data. The Omnibus Rule now allows them to have much greater autonomy and make decisions about how their medical information is communicated to them. If a patient is comfortable receiving information via E-mail this has previously presented a problem for healthcare companies. E-mails can be intercepted, the emails are often stored unsecured servers – where they can remain indefinitely – and there is no guarantee that the...

Read More
Mammoth HIPAA Data Breach Exposes 4M Patient Records
Aug26

Mammoth HIPAA Data Breach Exposes 4M Patient Records

Advocate Health Care, one of the nation’s largest healthcare providers, has announced that it has suffered a major HIPAA security breach after four unencrypted laptops were stolen from the Advocate Medical Group administrative buildings in Park Ridge, Illinois on July 15. The laptops contained the records of over 4 million individuals, making this the second largest data security breach ever recorded. This HIPAA breach has affected almost as many patients as the TRICARE Management Activity breach which exposed the data of 4.9 million individuals in 2011. The database on the laptops included personal identifiable information together with clinical data on patient illnesses, Social Security numbers, dates of birth, medical record numbers, treating doctors, health insurance details and patient names and addresses. The theft has been reported to law enforcement; however the laptops and data have not yet been recovered. The Office for Civil Rights of the Department of Health and Human Services has been notified of the security breach and officials have confirmed that an investigation...

Read More

BYOD Schemes Prove Popular With Nurses

According to a recent report from Spyglass Consulting, it is not just doctors who are embracing medical BYOD schemes; nurses too are now participating and 69% of those polled said they bring their own mobile device to work with them. Mobile devices cannot be used for all work activities, as the vast majority of healthcare providers operate strict controls over what the devices can be used for. One of their main uses is for organizing staff schedules and maintaining calendars, with more than half of healthcare staff using their devices for this purpose in addition to checking email according to healthcare mobile phone usage research conducted by Absolute Software. 36% said they were using the devices to access PHI. For PHI to be accessed without causing a HIPAA violation, additional security controls must be employed to secure the data being sent. Mobile phones are not secure, can easily be lost or stolen and the messages they send can be intercepted. Secure texting solutions exist, and these must be used for communicating any PHI via SMS message. E-mail encryption is also required...

Read More

53 Percent of Physicians Use a Smartphone, Tablet and Computer at Work

Doctors are clearly embracing new technology if the results of a recent survey are representative of the nation as a whole. Epocrates, a mobile reference material vendor, has recently conducted a survey on 1,063 mid-level practitioners and physicians asking them about the use of mobile devices in the workplace. The survey results show a marked increase in the usage of all mobile devices, with a particularly telling statistic being the percentage of doctors who are using all three types of device categorized in the study: Smartphones, tablets, and desktop/laptops. These “digital omnivores” as they are referred to in the study have increased from 28% in 2012 to 53% this year. As more healthcare providers implement BYOD schemes, or provide devices to healthcare professionals, the number of digital omnivores in healthcare is expected to increase, and significantly so according to Epocrates researchers. They predict the number will grow to 82% over the course of the coming year. Oncologists Most Likely to use Smartphones, Tablets and Desktops at Work Oncologists were the most...

Read More
Cogent Healthcare Contractor HIPAA Error puts Patient PHI in Search Engines
Aug09

Cogent Healthcare Contractor HIPAA Error puts Patient PHI in Search Engines

Cogent Healthcare has issued a statement announcing that M2ComSys, a contractor used for transcription services, was responsible for a HIPAA breach that exposed the data of 32,000 patients across America. The data breach not only left medical information accessible to unauthorized third parties, but it also saw some of that protected health information indexed by Google. This is the second reportable HIPAA data breach suffered by Cogent Healthcare, according to the Office for Civil Rights. The security breach occurred between May 5, 2013 and June 24, 2013, with data being made available due to a firewall not being activated. Without the firewall in place there were no restrictions as to who could access the data, which violates HIPAA Privacy and Security Rules. The data included personally identifiable information, medical record numbers, medical histories and patient contact details, although there were no Social Security Numbers present in the data. M2ComSys was employed to transcribe notes made by physicians and held the data on what it believed to be a secure server, although...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist